ZeroHour

CVE-2026-51747

Unauthenticated MQTT access-control flaw in TOTOLINK T6 mesh router keepAlive

CVSS 3.1
9.8 critical
EPSS
<1%p37
Published
()
Modified
AI analysis

CVE-2026-51747 is an incorrect access control flaw (CWE-284) in the keepAlive function of the MQTT-based cs_broker component in TOTOLINK T6 mesh routers running firmware 4.1.5cu.748_B20211015. An unauthenticated attacker who can reach the MQTT service can send a crafted MQTT message that causes the device to emit indirect mesh heartbeat information toward the master node, effectively letting an unauthenticated party inject or disclose mesh status traffic. The CVSS 3.1 score of 9.8 rates potential confidentiality, integrity, and availability impact as high, although no public exploit demonstrates the full scope of compromise. Any deployment of the TOTOLINK T6 on the affected firmware is affected, especially networks where the MQTT broker is reachable beyond the local LAN. Exploitation has not been observed: the flaw is not in CISA KEV, no public PoC is known, and EPSS assigns only a 0.4% probability of exploitation in the next 30 days.

What to do: Inventory TOTOLINK T6 units and identify any running firmware 4.1.5cu.748_B20211015, then upgrade to a patched firmware when TOTOLINK publishes one, as no fixed version is named in the current data. As an interim mitigation, restrict access to the cs_broker MQTT service by keeping MQTT ports off the WAN interface and limiting them to the trusted LAN, and monitor for unexpected MQTT/heartbeat traffic toward the master node. Track TOTOLINK advisories for a firmware release addressing this issue.

Affected
TOTOLINK T64.1.5cu.748_B20211015
Estimated exposure
unknown — plausibly on the order of tens of thousands of devices at most, but no public install-base or scan data exists for this model — No public active-install counts, market-share figures, or internet-scan data are available for the TOTOLINK T6 in the provided data; the only grounding is that this is a single documented firmware build of one consumer mesh router model…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect access control in the keepAlive function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to emit indirect mesh heartbeat information toward the master via sending a crafted MQTT message to the cs_broker component.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.